The Department of Health and Human Services has published new guidance on complying with HIPAA privacy, security and breach notification rules when using cloud computing technology.

The guidance gives insights for providers, business associates and cloud computing vendors. Some of the guidance is basic and well-known to many HIPAA-covered entities. The first question, for instance, considers if a HIPAA-covered entity or business associate may use a cloud service to store or process electronic protected health information (ePHI). The answer is yes, provided the vendor enters into a business associate agreement that specifies how HIPAA compliance will be maintained.

Register or login for access to this item and much more

All Information Management content is archived after seven days.

Community members receive:
  • All recent and archived articles
  • Conference offers and updates
  • A full menu of enewsletter options
  • Web seminars, white papers, ebooks

Don't have an account? Register for Free Unlimited Access